The state already issued the credential.
A digital identity programme usually begins by proposing a new database: faces, templates, enrolment, a procurement, and a twenty-year custody problem. There is a shorter route. The passport in the citizen’s drawer carries a chip the state signed with its own key, and that signature can be verified on a phone, offline, against the state’s own root. Nothing new has to be enrolled, and no face has to be stored.
Read the limit before the argument.
This page is written for an Israeli reader, so the first thing on it is the thing most vendors put last.
The Israeli ID card chip cannot be read.
It is locked to the state. Not locked to a vendor who has not been approved yet, not locked pending a pilot — locked, and not readable by JERIX or by anything else outside the state’s own systems. Any supplier telling a ministry that their app reads that chip is describing something that does not happen.
In JERIX, an Israeli ID card is therefore a photo-only verification: the printed document is captured and read, and the capture is signed on the device, but there is no chip signature behind it and it does not earn the chip-backed assurance level. The chip-backed path on this page means the passport, and every figure below belongs to the passport.
Nothing new to build.
The four systemic arguments for this route, in the order a budget office asks about them.
No new biometric database
Isolation between agencies
Works fully offline
What the counter was for.
A citizen attends in person for one reason: the service cannot otherwise be sure who is asking. Remove that uncertainty and most of the visit stops being necessary.
| Channel | How identity is established today | With a chip-backed check |
|---|---|---|
| counter | A clerk inspects a document by hand and judges a face. | The state's own signature is verified, and the visit is no longer the only way to establish who is asking. |
| telephone | Knowledge questions: an ID number, an address, a date. | Answers that a breached dataset already contains stop being the proof. |
| online | A password, sometimes a one-time code to a number on file. | A credential bound to a document the state issued, and to the device the capture was signed on. |
We have not measured a reduction in counter visits for any agency and we will not put a percentage on this page. The mechanism is what is on offer; the saving is yours to model against your own channel volumes.
Why the stored-biometrics question is not theoretical here.
The argument for keeping nothing is usually made in the abstract. In this market it was made for us, in court filings, in June 2026.
A 20-year-old was arrested in Israel after allegedly opening fraudulent bank accounts and drawing money from roughly 120 victims. He bought identity photographs out of breached databases, animated them with AI, and passed remote checks that were looking at an image handed to them.
The raw material for that attack was somebody else’s retained biometrics. A state programme that enrols faces into a central store is, among other things, manufacturing that raw material at national scale.
SOURCE: CALCALIST, 21.06.2026
| face images | None. Zero retention, verified on disk. |
|---|---|
| face templates or embeddings | None. |
| document images, chip data | None. |
| two face-derived hashes | Kept 30 days and 7 days, then gone. |
| name, national ID, date of birth | Retained encrypted, indefinitely. |
This is the whole list. It is why the claim is zero retention on images and biometrics, and never “we keep nothing”.
What a public-sector programme would be blocked on today.
A ministry evaluation reaches these four items on its own. Finding them written here is the point.
On-premises deployment
The core already verifies offline, which is most of what an air-gapped installation needs architecturally. That is not the same as a packaged, installed, operated deployment.
Not shippedOn-premises packaging. There are zero reference installations. We will not describe one, and we will not point you at a customer who has one, because there is none.
Single sign-on into existing government identity estates
The signing core ships. The federation surface an agency would actually bind to does not.
Not shippedSSO / OIDC / Entra endpoints. Blocked on the endpoints, not on the cryptography underneath them.
A published data-retention policy
The retention behaviour is settled and is stated above in full. The document that commits to it formally, in the form a government privacy officer files, is not written.
Not shippedData-retention policy as a published document. Blocked on drafting, not on behaviour.
External certification
Two founders, pre-certification. No audit has been started, and no badge appears anywhere on this site because none has been earned.
Not shippedSOC 2, ISO 27001, penetration test, iBeta ISO 30107-3. None held, none in progress.
Bring a passport and a network cable you can unplug.
The trust chain resolving with no connection is the demonstration. Twenty minutes, in Hebrew or English, with the limits above on the table from the first minute.
Request a walkthrough